IP Library Granted Patent US 10,116,448
Granted Patent B2
US 10,116,448 · App. 14/778,671 · Granted Oct 30, 2018

Transaction authorization method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,448
App. No.
14/778,671
Granted
Oct 30, 2018
Kind
B2
Abstract

Authorizing transactions by an authentication provider involves at least one preparatory phase and an authorization phase. The preparatory phase includes registering a user account with several personal devices, each with an authentication application installed. The authorization phase receives knowledge of the transaction; determines the user account related to the transaction; determines at least one personal device registered with the user account related to the transaction; receives a request for details specific to the transaction from at least one personal device; provides the authentication application of the at least one personal device with the requested details specific to the transaction; receives from the authentication application a digitally signed transmission which indicates transaction-specific instructions received by the authentication application; and authorizes or denies the transaction based on the received transaction-specific instructions.

Claims (70)

1. A method for authorizing a transaction, the method comprising the following acts performed by a telecommunications server configured to act as an authentication provider:

at least one preparatory phase; and

at least one authorization phase;

wherein the at least one preparatory phase comprises for each of several user accounts:

registering a user account via a user terminal;

registering a plurality of personal devices with the registered user account, wherein registering of a personal device comprises registering an authentication application installed in that personal device;

wherein the authentication application in the registered personal device is configured to:

indicate at least a subset of received transaction-specific details via a user interface;

receive transaction-specific instructions via the user interface; and

digitally sign the transaction-specific instructions by using a cryptographic private key assigned to the user account;

wherein the at least one authorization phase performed by the telecommunications server comprises for each of several transactions related to one of the several user accounts:

receiving knowledge of a transaction relating to a user of a user terminal;

determining, in response to receiving the knowledge, a user account related to the transaction;

receiving a request for details specific to the transaction from at least one personal device;

checking, whether the at least one personal device wherefrom the request is received belongs to the plurality of personal devices registered with the user account determined to relate to the transaction;

providing, in response to the at least one personal device wherefrom the request is received belonging to the plurality of personal devices registered with the user account determined to relate to the transaction, the requested details specific to the transaction to the authentication application in the at least one personal device wherefrom the request for details specific to the transaction were received;

receiving, after the providing, from the authentication application in the at least one personal device a digitally signed transmission which indicates transaction-specific instructions received via the user interface by the authentication application in the at least one personal device; and

authorizing or denying the transaction based on the received transaction-specific instructions.

2. The method according to claim 1 , further comprising establishing a trust relationship between the authentication provider and at least one service provider.

3. The method according to claim 2 , wherein said establishing the trust relationship comprises exchanging a shared cryptographic secret between the authentication provider and the at least one service provider.

4. The method according claim 2 , wherein said establishing the trust relationship comprises mutual authentication by means of one or more public key infrastructure certificates.

5. The method according to claim 1 , further comprising establishing a trust relationship between the authentication provider and the at least one authentication application.

6. The method according to claim 5 , wherein said establishing the trust relationship between the authentication provider and the at least one authentication application comprises provisioning a public key infrastructure certificate from the authentication provider to the authentication application.

7. The method according to claim 5 , wherein said establishing the trust relationship between the authentication provider and the at least one authentication application comprises using a shared secret key and authentication application private key.

8. The method according to claim 1 , wherein said registering of the authentication application comprises causing transmission of the authentication application to at least one of the registered personal devices.

9. The method according to claim 1 , wherein the authentication provider maintains a plurality of different security policies and applies a subset of the maintained security policies depending on a type and/or platform of the personal device that comprises the authentication application from which the authentication provider receives the digitally signed transmission.

10. The method according to claim 9 , wherein the subset of applied security policies requires one or both of:

performing the transaction using a first personal device and separately authorizing it using a second personal device, which is separate from the first personal device; and

authorizing the transaction by using at least two separate personal devices.

11. The method according to claim 9 , wherein the subset of applied security policies requires that the separate personal devices comprise at least two personal devices of a different type and/or platform.

12. The method according to claim 9 , wherein the subset of applied security policies requires that a personal device of a specific type and/or platform must be used or must not be used for authorizing the transaction.

13. The method according to claim 9 , wherein the subset of applied security policies depends on a financial value of the transaction and/or a history of the user account.

14. A data processing system comprising:

a memory system for storing program code instructions and data;

a processing system including at least one processing unit, wherein the processing system executes at least a portion of the program code instructions and processes the data;

wherein the memory system stores program code instructions that, when executed by the processing system, instruct the processing system to act as an authentication provider configured to perform the following acts:

at least one preparatory phase; and at least one authorization phase;

wherein the at least one preparatory phase comprises for each of several user accounts:

registering a user account via a user terminal;

registering a plurality of personal devices with the registered user account, wherein registering of a personal device comprises registering an authentication application installed in that personal device;

wherein the authentication application in the registered personal device is configured to:

indicate at least a subset of received transaction-specific details via a user interface;

receive transaction-specific instructions via the user interface; and

digitally sign the transaction-specific instructions by using a cryptographic private key assigned to the user account;

wherein the at least one authorization phase performed by the processing system comprises for each of several transactions related to one of the several user accounts:

receiving knowledge of a transaction relating to a user of a user terminal;

determining, in response to receiving the knowledge, a user account related to the transaction;

receiving a request for details specific to the transaction from at least one personal device;

checking, whether the at least one personal device wherefrom the request is received belongs to the plurality of personal devices registered with the user account determined to relate to the transaction;

providing, in response to the at least one personal device wherefrom the request is received belonging to the plurality of personal devices registered with the user account determined to relate to the transaction, the requested details specific to the transaction to the authentication application in the at least one personal device wherefrom the request for details specific to the transaction were received;

receiving, after the providing, from the authentication application in the at least one personal device a digitally signed transmission which indicates transaction-specific instructions received via the user interface by the authentication application in the at least one personal device; and

authorizing or denying the transaction based on the received transaction-specific instructions.

15. A non-transitory computer program carrier comprising program code instructions executable in a data processing system, which is operationally connectable to a user terminal, a plurality of personal devices managed by a user of the user terminal, and to at least one service provider, wherein execution of the program code instructions in the data processing system causes the data processing system to carry out a method, which comprises:

at least one preparatory phase; and

at least one authorization phase;

wherein the at least one preparatory phase comprises for each of several user accounts:

registering a user account via a user terminal;

registering a plurality of personal devices with the registered user account, wherein registering of a personal device comprises registering an authentication application installed in that personal device;

wherein the authentication application in the registered personal device is configured to:

indicate at least a subset of received transaction-specific details via a user interface;

receive transaction-specific instructions via the user interface; and

digitally sign the transaction-specific instructions by using a cryptographic private key assigned to the user account;

wherein the at least one authorization phase performed by the data processing system comprises for each of several transactions related to one of the several user accounts:

receiving knowledge of a transaction relating to a user of a user terminal;

determining, in response to receiving the knowledge, a user account related to the transaction;

receiving a request for details specific to the transaction from at least one personal device;

checking, whether the at least one personal device wherefrom the request is received belongs to the plurality of personal devices registered with the user account determined to relate to the transaction;

providing, in response to the at least one personal device wherefrom the request is received belonging to the plurality of personal devices registered with the user account determined to relate to the transaction, the requested details specific to the transaction to the authentication application in the at least one personal device wherefrom the request for details specific to the transaction were received;

receiving, after the providing, from the authentication application in the at least one personal device a digitally signed transmission which indicates transaction-specific instructions received via the user interface by the authentication application in the at least one personal device; and

authorizing or denying the transaction based on the received transaction-specific instructions.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED ON REEL 050980 FRAME 0452. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Nov 21, 2019
From: INSIDE SECURE
To: VERIMATRIX
Reel/Frame 051076/0018 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2019
From: MEONTRUST OY
To: INSIDE SECURE
Reel/Frame 050980/0229 →
CHANGE OF NAME Recorded Nov 12, 2019
From: INSIDE SECURE
To: VERIMATRIX
Reel/Frame 050980/0452 →
SECURITY INTEREST Recorded Feb 27, 2019
From: INSIDE SECURE
To: GLAS SAS, AS SECURITY AGENT
Reel/Frame 048449/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2017
From: MEHTÄLÄ, MARKKU
To: MEONTRUST INC.
Reel/Frame 041800/0210 →